Yeahlink
yeahlink
2 CVEs • 6 products
Products (6)
Click to collapseToggle
Products (6)
Click to collapse
CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Yeahlink 3T49g Firmware T58v FirmwareVp59 FirmwareJun 17, 2026 Oct 8, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement...Show more |
1Yeahlink 3T49g Firmware T58v FirmwareVp59 FirmwareJun 17, 2026 Oct 8, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP. |